A contractor for the U.S. Cybersecurity and Infrastructure Security Agency (CISA) inadvertently exposed credentials for AWS GovCloud accounts and internal systems on a public GitHub repository. The leak included plaintext passwords, cloud keys, and tokens that provide privileged access to sensitive government assets.
The repository also contained proprietary details regarding CISA’s internal software build and deployment processes. Security firm GitGuardian discovered the exposure, which was first reported by Krebs on Security.
Cybersecurity experts characterized the incident as a severe and egregious government data leak. CISA has taken the repository offline and is currently investigating the exposure. The agency stated there is no current indication that sensitive data was compromised.